EUVD Vulnerability Catalog

EUVD-2026-87102

Severity: CRITICAL Base Score: 9.3 CVSS Version: 3.1

Vulnerability Description

An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.

CVSS Vector Analysis

Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

▪ Attack Vector (AV): Network
▪ Attack Complexity (AC): Low
▪ Privileges Required (PR): None
▪ User Interaction (UI): Required
▪ Scope (S): Changed
▪ Confidentiality Impact (C): High
▪ Integrity Impact (I): High
▪ Availability Impact (A): None

Affected Vendors & Systems

Vendor Zimbra

References & Advisory Links

Metadata Profile

Database Authority

European Union Agency for Cybersecurity (ENISA) EUVD

Assigner

rapid7

EPSS Probability

0

Known Aliases
CVE-2026-93647 GHSA-h5jf-rfhh-rx8c
Published On

2026-09-25

Last Updated

2026-09-26